Executive brief
Budibase's plugin upload feature accepts a user-supplied filename that is not validated for path traversal sequences, allowing authenticated Global Builders to escape the intended temporary directory and delete arbitrary files or write files to sensitive locations. An attacker could overwrite application code or system files, potentially causing service outages or (in containerized environments running as root) enabling code execution on application restart.
Technical details
The POST /api/plugin/upload endpoint passes the user-supplied filename directly from the Content-Disposition header to createTempFolder() without sanitization, enabling path traversal via sequences like "../". The createTempFolder() function uses path.join() to resolve the filename against /tmp/.budibase, which does not prevent directory traversal, and then calls fs.rmSync() with recursive and force flags to delete any existing directory at that path, followed by fs.mkdirSync() and tarball extraction. An authenticated user with Global Builder privileges can craft a multipart upload with a malicious filename (e.g., "../../etc/target.tar.gz") to delete arbitrary directories and extract attacker-controlled tarball contents to arbitrary writable locations on the filesystem. The vulnerability was patched by sanitizing filenames, validating paths remain within the temp directory, and using fs.mkdtempSync() with random suffixes. Patches are available in version 3.33.4 and later.
Affected products
- Budibase Budibase <3.33.4
Timeline
- 2026-04-04: disclosed: Advisory published
- 2026-03-13: patched: Fix merged in PR #18240
- 2026-04-02: other: GitHub Security Advisory published